LWN.net Logo

php: missing input validation

Package(s):php CVE #(s):
Created:July 28, 2009 Updated:July 29, 2009
Description: From the php bug report: There seems to be a problem in exif_read_data(), where some fields representing offsets(?) are taken directly from the file without being validated, resulting in a segmentation fault.
Alerts:
Mandriva MDVSA-2009:167 2009-07-28

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds